About Carl Windsor
In a December 2023 Cube Conversation, Carl Windsor, Senior Vice President of Product Technology & Solutions at Fortinet, discussed the company’s approach to transparency in cybersecurity. He stated that Fortinet shipped 50% of all worldwide firewalls the previous year and described a "duty of care" to customers. Windsor said the company discovered 83% of the vulnerabilities it published were its own, adding that Fortinet does not hide issues and provides customers with information needed for risk-based decisions. He described the principle that "sunlight is the greatest disinfectant" and said the company works with outside partners on responsible disclosure.
Windsor acknowledged that customers find the pace of change "a little bit frenetic" and suggested that vendors can help by offering automatic upgrades and virtual patching technologies to give customers "breathing space" during upgrade processes. He emphasized that "radical transparency" is important for giving customers the information they need to make decisions about their security posture.
Source: AI-verified profile updated from Carl Windsor's recent appearances.
Browse all interviews →
Transcript (19 segments)
R
Rob Strechay0:12
I'm your analyst and host, Rob Strechay. I'm joined today by Suzanne Spaulding, former undersecretary for cyber and infrastructure at the Department of Homeland Security; and Carl Windsor, Senior Vice President of Product Technology & Solutions at Fortinet. Welcome, both of you.
S
Suzanne Spaulding0:31
Hello.
C
Carl Windsor0:32
Hey, Rob!
R
Rob Strechay0:33
I'm excited for this, because I think this is one of those really big moments in cyber that is about how we are going to achieve better resilience within our products, and how we are going to really get together. Here at theCUBE Research we have been discussing the threat landscape evolving in network and cyber security, and specifically examining how trust and confidence can be built by vendors into their products and solutions so that people can have more confidence going forward that they are approaching cyber in a way that helps everyone in a bigger-tent atmosphere. So let's get into it with Suzanne. With your background at the Department of Homeland Security, you had a unique viewpoint into this. Let's dive into that and get your view on the need for secure data and IP being balanced with the need for no more secrets and what some will call fighting into the light.
S
Suzanne Spaulding2:13
I think it's important to put this conversation in that broader context. I coined this phrase, I talk about it as training to fight in the light. I have been talking about this since 2010 or even earlier. The notion is pretty basic. If you train to fight in the dark, you could meet your adversary at night or you could turn off the lights and you would have the advantage. I think we need to recognize that a transparent world is coming at us full steam ahead, one in which the lights are being turned on all over the place, and whoever can figure out how to operate most effectively in a transparent world is going to have the advantage. Democracies are used to the imperatives for transparency, whereas dictators need dark corners in which to hide secrets from their public. So we have an advantage, and we should lean into that advantage. Part of that is coming to grips with the reality that that is the world coming at us. It is both because it is increasingly difficult to keep secrets, the shelf life of secrets is vanishingly short. We are all aware of that. But the costs of trying to keep information secret keep growing, both the direct costs of cybersecurity spending and the indirect costs. We got schooled on that after 9/11, where we recognized that we needed to share information with all of our defenders to increase our security. We see that in cybersecurity. It is absolutely the case that we need to be sharing that information with all of our network defenders. We need that radical transparency, because our adversaries are networked and sharing information. We need to share information that can help all of us do a better job in cybersecurity. It is absolutely imperative.
R
Rob Strechay4:51
Yeah, I think that is key. We are seeing that not only nation states, but these bad actors are more or less... But I think people may not really understand what transparency means in cyber, and you have been an advocate for the importance of this throughout your career. What does transparency look like in cyber and from a cyber vendor's perspective?
S
Suzanne Spaulding5:34
Yeah, so it is on both sides. One aspect is you have to assume, and really take on board the difficulty of keeping information secret. Therefore you have to identify and minimize the amount of information that you really need to protect, as opposed to trying to protect everything equally. Focus on protecting that kind of information. It also assumes that in your planning, you have to assume that you are going to have a breach, and you have to figure out all the ways to mitigate the consequences of that disruption. Those are two ways in which understanding this radical world of transparency is important for cybersecurity. And then on the flip side, making sure that you are sharing everything you possibly can leaning forward, that we are all sharing information about breaches, vulnerabilities, and threat information so that we can have collective defense, which is really our only hope.
R
Rob Strechay7:10
Now we are getting clean malware versus really badly worded malware, which was easier to track. But you are seeing it coming out of the LLMs. But let's bring Carl in on this, because I want to get a vendor's perspective. From a Fortinet perspective, how do you see that dynamic relationship between product security and the importance of transparency? You have intellectual property, trade secrets, but how do you strike the balance?
C
Carl Windsor7:46
Yeah, so Fortinet last year shipped 50% of all the worldwide firewalls, so we have a duty of care to our customers. We know that, so we have to balance security with transparency. That is really important to us. We have a saying: sunlight is the greatest disinfectant. So we will look at our products, look for vulnerabilities, work with our outside partners who are doing responsible disclosure. The key thing is to secure the products, look for issues, fix them rapidly, and then get as much information out to the customer as possible so they can assess the risk. Most importantly, they need to upgrade when necessary. If we do not give them that radical transparency that Suzanne talked about, they cannot make those risk decisions of when to upgrade and how quickly. We have to be transparent about vulnerabilities. Last year we discovered 83% of all the vulnerabilities that we published were actually our own. We are not hiding things. Other vendors may publish a crash or a bug, but we make sure that if there is any risk, we give our customers the information they need to make that risk-based decision.
R
Rob Strechay9:36
No, that's great. My morning reading of CISA emails, every vulnerability that came out the night before has been published, it is always fascinating to see. As a community, it seems like certain organizations are doing a better job. So it is great to hear how Fortinet is leaning into that. Suzanne, do you think more involvement from government entities is the right path forward or something that should be done?
S
Suzanne Spaulding10:18
Well, let me start by saying I think government can play an important role here by encouraging the kind of behavior that Carl just described, which is for companies to be quick to get out information about their own vulnerabilities. Government can help reduce the stigma attached with that. Everyone who is developing products, nobody is coding perfectly. So everyone has vulnerabilities, and the only real difference is are you being told about them as a customer? If you look at CISA's guidance on Secure By Design, one of their key principles is radical transparency. They explicitly note that when you first start implementing that, it is going to look ugly. I remember when I was the undersecretary at DHS, when we did it across government through our Continuous Diagnostics and Monitoring program, we began to get much greater insights into what was happening on our government networks. It was pretty ugly at first, but it was better to get that information out and share it widely to improve things. It was a sign of progress. So I think the message to the industry is that this radical transparency is going to look ugly at first, but that is a good thing, and it has to be done that way. Then government needs to lead by example, displaying that same radical transparency, being very transparent and quick about acknowledging breaches and vulnerabilities.
R
Rob Strechay12:31
Yeah, I do like the work that CISA has done. The White House had their foot in this with the National Cybersecurity Strategy that picked up on CISA and the secure by design and secure by default aspects. Having been a product person myself and built software over the years, transparency is a key foundation to both elements. Carl, can you share your insights into what is meant by secure by design and secure by default, and how you are going to meet those goals for cybersecurity from an industry perspective?
C
Carl Windsor13:33
From our point of view, secure by design is something we have had in place for a long while. It is about thinking about security before you even write a line of code, right at the start where you think of how you are going to design the system, what methodology you will use, threat model what you expect the threats to be on your product. That is something we have been doing for a long time. Secure by default is about making the product secure out of the box. Historically, vendors have created hardening guides, building products that are simple for customers to use and then having a hardening guide to make them more secure over time. We have to move away from that and take the onus from the customer for that initial secure configuration. Build security into the product from the start, and then have a loosening guide for customers who want to trade security for ease of use. It is a whole paradigm shift for the way we operate in the cybersecurity space, and one that is going to be a big benefit for a long time to come.
R
Rob Strechay15:23
Yeah, I would agree. From the past when I managed firewalls in a very distant past life, you shut the ports off and let somebody complain about the port not being open. That was the poor man's view back in the day. But Carl, do you expect the rate of change to be challenged with this? The pace of patches and disclosures?
C
Carl Windsor16:12
I think the pace of change has got to continue. The difficulty for our customers is how they manage that pace of change. We can create patches and continue to fix issues, but as we speak to our customers, they are finding the pace a little bit frenetic. We cannot get away from that. So what we need to do is give them the tools they need to make the decision of whether they need to upgrade and how quickly, and then put other mitigations in place. Things like automatic upgrading to get them to the next release as rapidly as possible, and other tools like virtual patching technologies. That does not get away from the need to upgrade, but it gives them time to make those decisions. So give them the information as early and rapidly as possible so they can make those risk-based decisions. Yes, the pace has got to continue. It is okay to say, 'I am not going to patch for this release,' or 'I don't have time to patch,' but threat actors are going to abuse that gap between updates. So the more we can do to keep the pace of fixing problems, give customers the information they need to make risk-based decisions, and provide other tooling like virtual patching to mitigate risks in between, that is absolutely critical.
R
Rob Strechay17:56
Yeah, we like to say that recommending radical transparency and rating the organizations you work with on that radical transparency is important. Because that is one of the things you want to see, that they are participating in that. So I want to thank you both, Suzanne and Carl, for coming on board. This has been a ton of fun and flew by, but I really appreciate you sharing some of the insights into that and what others can look for when they are looking at vendors.
S
Suzanne Spaulding18:43
Thank you, thanks for the time.
C
Carl Windsor18:45
Thanks, Rob.
R
Rob Strechay18:46
And thank you for watching this Cube Conversation. I'm your analyst and host Rob Strechay. You're watching theCUBE, your leader in enterprise technology news and analysis. See you soon.